CVE-2023-37304: XSS
Published Jun 30, 2023
·Updated
An issue was discovered in the DoubleWiki extension for MediaWiki through 1.39.3. includes/DoubleWiki.php allows XSS via the column alignment feature.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.39.3
Remediation
Patch Available
Event History
Jun 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-37304.
2
What is the affected software?
The affected software is MediaWiki.
3
What is the severity of CVE-2023-37304?
The severity of CVE-2023-37304 is medium.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through a cross-site scripting (XSS) attack via the column alignment feature.
5
Is there a fix available?
Yes, a fix for this vulnerability is available. It is recommended to update to Mediawiki version 1.39.3 or later.